contao/core-bundle Security Advisories for 5.3.40 (4)
-
Server-side request forgery (SSRF) via unvalidated RSS feed URLs
PKSA-yx24-z15d-x2k7 CVE-2026-57232
Affected version: >=5.3.35,<5.3.48|>=5.4.0,<5.7.9
Reported by:
FriendsOfPHP/security-advisories -
Credentials disclosure in the crawler
PKSA-f8tt-pn3h-s2tw CVE-2026-55824
Affected version: >=4.13.0,<5.3.47|>=5.4.0,<5.7.7
Reported by:
FriendsOfPHP/security-advisories -
[LOW] Contao is vulnerable to cross-site scripting in templates
PKSA-3p5h-vgz7-458z CVE-2025-65961 GHSA-68q5-78xp-cwwc
Affected version: >=5.4.0-RC1,<5.6.5|>=5.0.0-RC1,<5.3.42|>=4.0.0,<4.13.57
Reported by:
GitHub -
[MEDIUM] Contao is vulnerable to remote code execution in template closures
PKSA-wjhx-cdbz-9x61 CVE-2025-65960 GHSA-98vj-mm79-v77r
Affected version: >=5.4.0-RC1,<5.6.5|>=5.0.0-RC1,<5.3.42|>=4.0.0,<4.13.57
Reported by:
GitHub